Skip to content

Fix panic on out-of-range '@' Unix timestamp in time filters - #2082

Merged
tmccombs merged 2 commits into
sharkdp:masterfrom
nikolauspschuetz:fix-changed-time-overflow-panic
Aug 9, 2026
Merged

tmccombs merged 2 commits into
sharkdp:masterfrom
nikolauspschuetz:fix-changed-time-overflow-panic

Conversation

@nikolauspschuetz

Copy link
Copy Markdown
Contributor

Fixes #2081.

Bug

fd panics instead of failing gracefully when a @-prefixed Unix timestamp passed to --changed-before / --changed-within is large enough to overflow SystemTime:

$ fd --changed-before "@18446744073709551615" . /tmp
thread 'main' panicked at library/std/src/time.rs:614:31:
overflow when adding duration to instant

Fix

In src/filter/time.rs, the @-timestamp branch of TimeFilter::from_str used UNIX_EPOCH + Duration::from_secs(...); SystemTime's Add<Duration> panics on overflow. Every other branch in that function already fails softly via .ok()? — this one didn't.

Switched to UNIX_EPOCH.checked_add(...), which returns Option, so an out-of-range value propagates None through the existing ? and is rejected like any other unparseable time input (no behavior change for valid timestamps).

Test

Added out_of_range_unix_timestamp_is_rejected, asserting TimeFilter::before/after with @{u64::MAX} return None. Verified it panics on master without the fix and passes with it; cargo test --bin fd filter::time is green and cargo fmt --check is clean.

CHANGELOG updated.


🤖 Disclosure (per CONTRIBUTING §4): the bug was found and the fix drafted with the help of an AI coding assistant; I reviewed it, reproduced the panic and the fails-before/passes-after behavior myself, and understand the change. This PR text is my own.

Demonstrates that a '@'-timestamp large enough to overflow SystemTime
panics ('overflow when adding duration to instant') instead of being
rejected like other unparseable time inputs. See sharkdp#2081.
Use UNIX_EPOCH.checked_add(...) so an out-of-range value returns None
and propagates through the existing ? like every other parse failure in
TimeFilter::from_str, rather than panicking via SystemTime's Add. See sharkdp#2081.
@nikolauspschuetz
nikolauspschuetz force-pushed the fix-changed-time-overflow-panic branch from 9a22c99 to 5becb9d Compare July 30, 2026 15:06
@tmccombs
tmccombs marked this pull request as ready for review August 9, 2026 07:31
@tmccombs
tmccombs merged commit ee195f4 into sharkdp:master Aug 9, 2026
18 of 19 checks passed
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
fd 10.5.0

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre>## Features
- Add `--ignore-parent` option to override `--no-ignore-parent`, see #1958 (@tmchow)
- Add `--exact` option to match the entire filename exactly (literal, non-substring).

## Bugfixes
- Sanitize control characters and bidirectional override characters in filenames
  when output goes to a terminal, to prevent terminal escape-sequence injection.
  Also reject a placeholder as the executable for `--exec-batch`, while still
  allowing it for `--exec`.
- Handle invalid working directories gracefully when using `--full-path`, see #1900 (@Xavrir).
- Fire the "search pattern contains a path separator" diagnostic for any pattern containing `/`, not just patterns that happen to name an existing directory. Preserves the legacy Windows behaviour that also flags native `\` separators when the pattern resolves to a real directory. See #1873.
- Also fire the "search pattern contains a path separator" diagnostic for `--and` patterns, not only the primary positional pattern. `--and` patterns are matched against the file name just like the primary pattern, so a path separator in them silently returned zero results. See #1873.
- Fix bug where passing "-" as a directory argument didn't actually search that directory, see #849 (@Sean-Kenneth-Doherty).
- Fix panic when `--changed-before`/`--changed-within` is given an out-of-range `@` Unix timestamp; the value is now rejected gracefully, see #2081 (@nikolauspschuetz).


## New Contributors
* @liruiluo made their first contribution in sharkdp/fd#1924
* @Xavrir made their first contribution in sharkdp/fd#1917
* @rexkirshner made their first contribution in sharkdp/fd#1921
* @Rohan5commit made their first contribution in sharkdp/fd#1934
* @tmchow made their first contribution in sharkdp/fd#1959
* @YoshKoz made their first contribution in sharkdp/fd#1979
* @SAY-5 made their first contribution in sharkdp/fd#1975
* @skane-lukas made their first contribution in sharkdp/fd#1889
* @Sean-Kenneth-Doherty made their first contribution in sharkdp/fd#2006
* @stevenwalton made their first contribution in sharkdp/fd#2011
* @DeflateAwning made their first contribution in sharkdp/fd#1983
* @wyf027 made their first contribution in sharkdp/fd#2001
* @bonanza127 made their first contribution in sharkdp/fd#2040
* @mahirhir made their first contribution in sharkdp/fd#2036
* @parneetsingh022 made their first contribution in sharkdp/fd#2037
* @curious-rabbit made their first contribution in sharkdp/fd#1976
* @WilliamLeony made their first contribution in sharkdp/fd#2064
* @kobihikri made their first contribution in sharkdp/fd#2063
* @cmelaro made their first contribution in sharkdp/fd#2075
* @nikolauspschuetz made their first contribution in sharkdp/fd#2082

**Full Changelog**: https://github.com/sharkdp/fd/compare/v10.4.2...v10.5.0</pre>
  <p>View the full release notes at <a href="https://github.com/sharkdp/fd/releases/tag/v10.5.0">https://github.com/sharkdp/fd/releases/tag/v10.5.0</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!17790
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Panic on out-of-range '@' Unix timestamp in --changed-before/--changed-within

2 participants